Prepare for your next ISO 9001 internal audit with a practical, clause-by-clause checklist covering the QMS requirements, audit questions, objective evidence, findings, and corrective actions.
Whether you are preparing for an internal audit, a certification audit, a surveillance audit, or simply evaluating the effectiveness of your Quality Management System, this checklist can help your audit team organize the review and identify areas requiring attention.
ISO 9001 update: ISO 9001:2026 is now the current edition of the standard. Organizations transitioning from ISO 9001:2015 should confirm applicable transition arrangements with their certification body.
An ISO 9001 audit checklist is a structured set of questions and evidence prompts used by auditors to assess whether an organization's Quality Management System (QMS) is effectively implemented and conforms to applicable ISO 9001 requirements.
A good audit checklist should do more than ask whether a procedure exists.
It should help the auditor determine:
This checklist is designed as a practical starting point for internal auditors. It should be adapted to the organization's scope, processes, products, services, risks, and applicable requirements.
ISO 9001 requirements are organized around the organization's context, leadership, planning, support, operation, performance evaluation, and improvement.
Use the following checklist to guide an internal audit.
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Common audit risks
Look particularly for:
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Questions for the auditor
For each audit, consider asking:
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
Audit questions
Objective evidence to consider
A useful CAPA audit trail
A strong corrective-action record should allow an auditor to follow the complete chain:
Problem → Containment → Investigation → Root Cause → Corrective Action → Implementation → Effectiveness Check → Closure
Audit questions
Objective evidence to consider
An audit should not stop when a checklist question has been answered.
When an auditor identifies an issue, the finding should be documented with enough information for the organization to understand and address it.
Depending on the organization's audit methodology, findings may be classified as:
A useful finding record can include:
| Field | Purpose |
|---|---|
| Finding Number | Unique identification |
| Audit | Links finding to the audit |
| Clause / Requirement | Identifies the relevant requirement |
| Process / Department | Identifies where the finding occurred |
| Finding Type | Nonconformity, observation, etc. |
| Description | Clear statement of what was found |
| Objective Evidence | Evidence supporting the finding |
| Responsible Person | Owner of follow-up |
| Target Date | Required completion date |
| Corrective Action | Action required |
| Root Cause | Cause of the problem |
| Effectiveness | Verification that action worked |
| Closure | QA/auditor closure |
For significant or recurring findings, the audit process may need to connect to the organization's nonconformance and CAPA processes.
A practical workflow is:
Audit → Finding → NCR → Investigation → Root Cause Analysis → Corrective Action → Effectiveness Analysis → Closure
This creates traceability between the original audit requirement and the corrective action taken.
It also helps Quality teams answer an important audit question:
"Show me what happened to this finding after it was identified."
Before beginning the audit, the audit team should consider:
Audit scope
Audit criteria
Audit team
Audit evidence
Prepare to review:
A common mistake during internal audits is checking only whether a procedure exists.
An effective audit should examine both documented information and actual implementation.
For example:
| Procedure says: | Auditor should check: |
|---|---|
| Documents must be approved before release. | Are current documents actually approved before employees use them? |
| Employees must be trained on revised documents. | Can the organization demonstrate training or awareness for affected personnel? |
| CAPA effectiveness must be evaluated. | Is there objective evidence that the corrective action actually addressed the cause? |
The objective is to determine whether the QMS is implemented and effective, not merely documented.
A checklist is useful for preparing and conducting an audit. The larger challenge is managing everything that happens before, during and after the audit.
LuitBiz QMS brings these quality processes together in one system.
| Process | How LuitBiz QMS Helps |
|---|---|
| Audit Management | Create audits, define audit scope and criteria, assign checklist items or clauses to auditors, record evidence and findings, assign actions and track closure. |
| Document Control | Control SOPs, policies, forms and other quality documents with controlled versions, approvals, access and audit history. |
| Nonconformance Management | Record nonconformities from audits, production, suppliers, customers or other quality processes and track them through investigation and disposition. |
| CAPA | Manage corrective and preventive actions with responsible persons, target dates, root cause analysis, action tracking and effectiveness review. |
| Supplier Quality | Track supplier evaluations, supplier issues, nonconformances and corrective actions. |
| Complaint Management | Capture customer complaints and connect them to investigations, root causes and corrective actions where required. |
| Change Control | Manage quality-related changes through controlled requests, review, approval, implementation and records. |
| Quality Dashboards | Give Quality and management visibility into audits, findings, NCRs, CAPAs, overdue actions and quality trends. |
The result is a connected quality workflow rather than a collection of separate spreadsheets, documents and email threads.
Use this page as a starting point for your internal audit planning and customize the checklist to your organization's QMS, processes, risks, products and applicable requirements.
Download the free ISO 9001 Audit Checklist and use it to prepare your next internal audit by submitting the following form.
Important: This checklist is provided for general informational and audit-preparation purposes. It is not a substitute for the ISO 9001 standard, professional auditing guidance or advice from your certification body. Organizations should use the current applicable edition of ISO 9001 and determine how its requirements apply to their QMS.
An ISO 9001 audit checklist is a structured set of audit questions and evidence prompts used to assess whether an organization's Quality Management System conforms to applicable ISO 9001 requirements and is effectively implemented.
A comprehensive checklist should address the applicable requirements in clauses 4 through 10, covering the organization's context, leadership, planning, support, operation, performance evaluation and improvement.
This checklist is structured around the clause framework of ISO 9001 and is designed to support audits against the current edition. ISO 9001:2026 was published in September 2026 and replaced ISO 9001:2015 as the current edition. Organizations transitioning from the previous edition should confirm applicable transition requirements with their certification body.
Objective evidence is information that can be verified and used to demonstrate whether a requirement is being fulfilled. Examples include records, documents, system data, observations, measurements, interviews and other verifiable information.
The organization should evaluate the finding, determine the appropriate correction or containment, investigate the cause where required, implement corrective action and verify effectiveness before closure.
Not necessarily. The organization's QMS should define how findings and nonconformities are handled. The significance, recurrence, risk and nature of a finding can determine whether a formal corrective action or CAPA process is required.
ISO 9001 does not prescribe one universal audit frequency for every process or organization. The internal audit program should consider factors such as process importance, changes affecting the organization, previous audit results and other relevant risks.
No. A checklist is an audit aid. An effective audit also requires competent auditors who can evaluate objective evidence, understand the organization's processes and determine whether requirements are effectively implemented.
Yes. LuitBiz QMS is designed to support quality processes including document control, audit management, nonconformance management, CAPA, supplier quality, complaints, change management and quality dashboards.